Unrated severityNVD Advisory· Published May 23, 2024· Updated Sep 18, 2024
Cross-Site Request Forgery (CSRF) in GitLab
CVE-2023-7045
Description
A CSRF vulnerability exists within GitLab CE/EE from versions 13.11 before 16.10.6, from 16.11 before 16.11.3, from 17.0 before 17.0.1. By leveraging this vulnerability, an attacker could exfiltrate anti-CSRF tokens via the Kubernetes Agent Server (KAS).
Affected products
3- Range: >=13.11, <16.10.6; >=16.11, <16.11.3; >=17.0, <17.0.1
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
2- hackerone.com/reports/2286823mitretechnical-descriptionexploitpermissions-required
- gitlab.com/gitlab-org/gitlab/-/issues/436358mitreissue-trackingpermissions-required
News mentions
1- GitLab Patch Release: 17.0.1, 16.11.3, 16.10.6GitLab Security Releases · May 22, 2024